Live data from Hacker News

Delta Dental says data breach exposed info of 7M people

bleepingcomputer.com

101–110 of 152 posts

Re: Delta Dental says data breach exposed info of 7M people

#101
post #3

Wow that MoveIT hack sure was bad. How did they manage to keep from becoming a punching bag like SolarWinds? Also the title should probably clarify this is Delta Dental of California.

The title is borderline click-bait: I have had Delta Dental insurance at every employer, so I clicked through to read more, but I've never lived in California or been employed by a California company.

Did the title say your info was leaked?

Re: Delta Dental says data breach exposed info of 7M people

#102
post #100
post #93

Earlier quoted context omitted.

Yeah... it's a complete PITA. I also had the 'we can't freeze right now' and it took a few days of verification and eventually having to call them to get it all sorted. My reasoning is it's better to do this before a bad person has your account rather than during.

Why are you doing so much work to save some third party money when they get defrauded?

Because you'll have to deal with the repercussions. I'd rather not.

Re: Delta Dental says data breach exposed info of 7M people

#103

> who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental should be rightly and truly f'd for that one. Storing security codes at all is totally forbidden by PCI rules. Delta Dental should have their ability to process credit cards completely revoked for this egregious breach.

I use delta dental. What does this mean? Why would they store my CC info when I’m paying directly to my dentist and delta dental is also paying the dentist? How does my CC info get transferred to the insurer? There’s no such transaction afaik.

How are you paying your premium? For individual plans, I suspect that a lot of people use a card.

Re: Delta Dental says data breach exposed info of 7M people

#104

Surely the data breaches we hear about are the tip of the iceberg? Just think of what needs to happen after a hack for you to hear about it: - someone at the company needs to be aware it has happened. - they need to accurately identify what was accessed. - they need to disclose that this has happened. - it needs to be visible enough that it gets picked up and talked about. Each step of that funnel must have some drop…

And finding out shouldn't be like pulling teeth.

Re: Delta Dental says data breach exposed info of 7M people

#105
Great example of why you should never ever ever give out a debit card number for anything. Just about every credit card company has virtual numbers now. And even still, there's a massive difference between disputing a credit charge and replacing lost funds in a checking account.

Re: Delta Dental says data breach exposed info of 7M people

#106
post #32

Earlier quoted context omitted.

The real question is why online credit card payments still involve using the whole card number, as opposed to some message signed by the card's private key authorizing certain spending limits for a retailer.

Online retailers almost surely do better by allowing easy use of credit cards by even the least technical 5% of Americans than they would from a lower fraud system that required a moderate or higher level of technical acumen to operate. Suppose I'm at a computer ready to buy a PS5 on BestBuy's site. What's the complexity now vs under a proposed private-key system? What's the loss in conversion rate on the latter?

I'm not sure exactly what that might look like, but if you look at crypto wallets for example, you could have a browser extension (or something like Apple Pay) that's able to custody the private key and sign transactions. Once you have it set up, it would be much easier than entering a CC number.

Re: Delta Dental says data breach exposed info of 7M people

#107

Earlier quoted context omitted.

Why they are doing their own payments processing is beyond me. Is it just too expensive to use someone like Stripe?

I was going to ask something similar. Especially US companies seems rather fond of storing credit card information, but I never seem it done in Denmark, regardless of the size of the company. The most common solution is to let your payment processor deal with those sorts of things, you just have a token, which can only be used to deposit money into your account. So even if it's stolen or leaked, you can transfer the…

For a long time, payment processors in the US would charge more to offer tokenization services. Cost-conscious companies with an eye on their unit economics reacted in predictable ways.

Re: Delta Dental says data breach exposed info of 7M people

#108

Earlier quoted context omitted.

You're not wrong, but GP is saying that 3 digits is a pretty weak 'security' code and gas station skimmers are on the tail end of the threat model compared to exfil of data at any point in the processing chain.

I tried to better clarify what I'm saying in [1]. I'm not saying the small number of digits makes it insecure, it's that "moar numbers" is not really adding anything in terms of multi-factor or secrecy. Instead of knowing N digits, you merely need to know N+M digits. It is not changing the nature of the secret. 1: https://news.ycombinator.com/item?id=38655609

I think this topic came up a week or 2 ago, and I made an almost identical comment as you, which was why the content of my reply was fresh in my memory. Anyway, in the recent convo, a kind hn poster provided this explanation of CVV

https://randomoracle.wordpress.com/2012/08/25/cvv1-cvv2-cvv3...

I totally see why it just seems like "moar numbers" though, and I find them unnecessarily annoying. I wish they could reduce the complexity (maybe letters, colors or shapes, something more human-compatible), but there's just too much legacy code with too little benefit.

Re: Delta Dental says data breach exposed info of 7M people

#109

Earlier quoted context omitted.

At one time it was routine to have your SSN and Drivers License # printed on your checks. And in 1988 my student ID number as university was my SSN.

But 1988 is officially The Past, ask any millennial, my self image can’t deal with the fact that our anecdotes objectively belong side-by-side.

At the risk of instantly drying into dust by suggesting that 2002 is also The Past, but my SSN was also my student ID then.

Re: Delta Dental says data breach exposed info of 7M people

#110
Delta Dental is one of the worst dental insurance companies out there. I hope it goes bankrupt. They have cut benefits so much that most dentists I know have dropped them completely and refuse to take them. It has caused a bunch of headaches for us and for most families I know.
Post reply on HN